Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.0%—Cisco Content Services Switch 115002/11/200516/6/2026
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.
ModificadaAlta (7.5)2.5%💥 ExploitInvision Power Services Invision Gallery1/11/200516/6/2026
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.
ModificadaMedia (5)42%—Microsoft Internet Information ServerMicrosoft Internet Information Services23/8/200516/6/2026
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
ModificadaMedia (5)2.2%💥 ExploitInvision Power Services Invision Board10/8/200516/6/2026
Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.
ModificadaMedia (4.3)31%—Microsoft Internet Information Services5/7/200516/6/2026
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a…
ModificadaAlta (7.5)25%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
El desbordamiento de búfer en Microsoft Step-by-Step Interactive Training (orun32.exe) permite a los atacantes remotos ejecutar código arbitrario a través de un archivo de enlace de marcadores (extensión.cbo, cbl o.cbm) con un campo de usuario largo.
ModificadaMedia (5.1)13%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Microsoft Agent permite a los atacantes remotos falsificar contenido de Internet de confianza y ejecutar código arbitrario disfrazando las indicaciones de seguridad en una página web maliciosa.
ModificadaAlta (7.5)1.2%💥 ExploitInvision Power Services Invision Gallery9/6/200516/6/2026
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.
ModificadaAlta (7.5)1.3%—Invision Power Services Invision Community Blog9/6/200516/6/2026
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.
ModificadaMedia (4.3)1.2%—Invision Power Services Invision Community Blog9/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.
ModificadaAlta (7.4)16%💥 PoCMicrosoft Remote Desktop ConnectionMicrosoft Windows Terminal Services Using RDP1/6/200516/6/2026
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
ModificadaMedia (4.6)0.50%—Invision Power Services Invision Board1/6/200516/6/2026
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.
ModificadaMedia (5)1.9%💥 ExploitInvision Power Services Invision Board1/6/200516/6/2026
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaMedia (4.3)2.4%💥 ExploitInvision Power Services Invision BoardInvision Power Services Invision Power Board16/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.
ModificadaAlta (7.5)14%💥 ExploitInvision Power Services Invision BoardInvision Power Services Invision Power Board16/5/200516/6/2026
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.
ModificadaAlta (7.5)1.2%—Cisco Firewall Services Module11/5/200516/6/2026
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).
ModificadaMedia (4.6)0.59%—HP Openview Event Correlation Services3/5/200516/6/2026
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.
ModificadaMedia (4.3)20%—Microsoft Sharepoint Portal ServerMicrosoft Sharepoint Team Services2/5/200516/6/2026
Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.
ModificadaMedia (4.3)1.3%💥 ExploitInvision Power Services Invision Board2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.
ModificadaAlta (7.5)1.3%—Invision Power Services Invision Community Blog2/5/200516/6/2026
SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.
ModificadaMedia (5)1.2%—IRC Services Nickserv Listlinks2/5/200516/6/2026
Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.
ModificadaAlta (7.5)1.1%💥 ExploitInvision Power Services Invision Board11/4/200516/6/2026
SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter.
ModificadaMedia (4.3)2.4%💥 ExploitInvision Power Services Invision Power Board30/3/200516/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una etiqueta IMG en una etiqueta COLOR cuyo estilo está puesto como background:url.
ModificadaAlta (7.5)23%—Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+631/12/200416/6/2026
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.